From owner-freebsd-questions@FreeBSD.ORG Tue Sep 15 12:34:43 2009 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id DD4781065672 for ; Tue, 15 Sep 2009 12:34:43 +0000 (UTC) (envelope-from mel.flynn+fbsd.questions@mailing.thruhere.net) Received: from mailhub.rachie.is-a-geek.net (rachie.is-a-geek.net [66.230.99.27]) by mx1.freebsd.org (Postfix) with ESMTP id AED3C8FC08 for ; Tue, 15 Sep 2009 12:34:43 +0000 (UTC) Received: from smoochies.rachie.is-a-geek.net (mailhub.lan.rachie.is-a-geek.net [192.168.2.11]) by mailhub.rachie.is-a-geek.net (Postfix) with ESMTP id 134FC7E818; Tue, 15 Sep 2009 04:34:56 -0800 (AKDT) From: Mel Flynn To: freebsd-questions@freebsd.org Date: Tue, 15 Sep 2009 14:34:41 +0200 User-Agent: KMail/1.12.1 (FreeBSD/8.0-BETA4; KDE/4.3.1; i386; ; ) References: <4AAF4927.3070203@frasunek.com> In-Reply-To: <4AAF4927.3070203@frasunek.com> MIME-Version: 1.0 Content-Type: Text/Plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Message-Id: <200909151434.41177.mel.flynn+fbsd.questions@mailing.thruhere.net> Cc: Przemyslaw Frasunek Subject: Re: reporter on deadline seeks comment about reported security bug in FreeBSD X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 15 Sep 2009 12:34:43 -0000 On Tuesday 15 September 2009 09:58:31 Przemyslaw Frasunek wrote: > Giorgos Keramidas wrote: > > Przemyslaw should email security-officer with any details he thinks are > > relevant. Then the security team will make sure to fix the bug for all > > affected releases of FreeBSD, release a patch with the fix, issue an > > advisory through the usual channels, and post the details online at our > > security information web pages at . > > I see that I received a lot of criticism after disclosing 6.4 > vulnerability. Please read some facts: FWIW, I think some people here read with their eyes closed and I'm wondering myself, why security@ did not at least respond with a "we're looking into it, please hold on, as we're busy with 8.0 release.". -- Mel